Originary Investigate · preview

Turn a disputed agent action into a reviewable evidence case.

Bring together existing records, identify what they support, and give another team a clear way to inspect the findings and missing evidence.

Open-source preview: source link published with the public release.

evidence-casesynthetic example
Question
Did the rollback restore the flags config?
Contradicted
1 finding
Supported
1 finding
Not established
1 finding
Signature
checked against the key you supply
fictional systems and people
Disputed agent actionsCited findingsMissing evidenceRecipient decision
The example

One disputed action, read from the records.

A coding agent told a customer it had rolled back a configuration change. The deployment records disagree. The recipient needs to decide whether to accept the incident explanation or ask for more evidence.

Synthetic example · fictional systems and people
Question for review

Did the agent's rollback restore the production flags configuration, as the agent reported to the customer?

  1. Contradicted

    The agent's rollback reverted the change to the flags configuration.

    The agent's message says so. The path it restored, the commit it made and the deploy that followed all touched a different file.

  2. Supported

    After the rollback, production still ran the changed flags configuration.

    The last write of that file in the covered window is the earlier deploy. Bucket write logging covered the whole window.

  3. Not established

    Secret values left the developer endpoint during the session.

    The agent read the secrets file, but no source covering data leaving the endpoint was supplied. This stays open rather than being guessed.

The useful moment is seeing a plausible claim fail to become an established finding merely because a transcript says it happened. This page shows a summary; the synthetic case itself ships with the open-source preview as a signed bundle a recipient can check locally.

A claim is not a finding because a transcript says so.

How a review works

Question, records, handoff.

01

Define the question

One question the recipient must decide, the time window, who receives the handoff and what is out of scope. Sources you expected but could not get are recorded, not ignored.

02

Review the records

Existing exports are kept byte-for-byte. Each finding cites the records it relies on, shows contrary records, and says what would settle it. Two views of one observation are not counted as corroboration.

03

Hand off findings and limits

The recipient opens the findings, follows each citation to its source, sees what verification checked and what it could not, and records a decision for a stated purpose.

What the recipient sees

The person deciding does not learn the investigator's tools.

They get five views: the question, the findings, the cited sources, verification, and their response.

recipient view · verificationillustration
Files
✓ Match the manifest
Signature
✓ Valid under the key you supplied. A key inside the bundle is never trusted automatically.
Records rebuilt
✓ Re-derived from the included bytes
Human review
2 of 3 findings reviewed by a second analyst
Not checked
Whether the sources are complete, whether the events occurred, who holds the key
No single "verified" badge: each result is reported separately.
recipient view · responseillustration
Decision
  • Accept for a stated purpose
  • Request more evidence
  • Reject
  • Defer
Required
A purpose and a reason
Saved as a separate file bound to the exact bundle and finding revision. It never changes the findings.

Because the response is bound to a specific revision, the investigator can tell when it goes out of date.

Data boundary

Where your evidence stays.

  • Local-first software. Investigate runs on your machine or in your approved environment. It needs no account, makes no network requests and keeps originals unchanged.
  • Assisted work under an agreed scope. For a scoped review we agree the question, sources, access, transfer and retention before any evidence is handled.
  • No evidence upload here. This page has no upload form. Please do not send incident logs or credentials with a first request.
  • Disclosure you control. Redacted handoffs can withhold whole sources or mask values. The recipient is told what was withheld and what therefore could not be rebuilt.
Engagement

Two ways to start.

Originary Investigate

Review a disputed action with existing evidence

One bounded engagement. We agree the scope and a fixed fee with you before any evidence is handled.

  • One case and one agreed question set
  • Up to three agreed source types or exports
  • Findings with their limits, and the checks that can be repeated
  • A disclosed bundle and report for the recipient
  • One recipient review session and one revision
  • About five business days once agreed inputs and access are available

Not included: emergency containment, continuous monitoring, unrestricted collection, legal opinions or insurance determinations. The work is accepted against the agreed scope, not a favourable conclusion; “not established” is a legitimate outcome.

Verification Pilot

Record one workflow so future evidence is easier

The Verification Pilot adds signed records to one existing workflow, so the next dispute starts with records built to be checked. See an illustrative evidence case or verify a record.

Neither path requires adopting the whole PEAC stack up front.

Request

Request a scoped review.

Tell us a little about the situation. We decide on any evidence transfer only after we agree the scope.

Do not include credentials or incident logs. A short, non-sensitive description is enough.
Two or three sentences, without sensitive details. Up to 800 characters.

This opens an email to contact@originary.xyz in your mail app, with your answers filled in. Nothing is sent from this page.

Preview status

Status and limits.

TopicDetail
statusInvestigate is a pre-release (0.2 preview). Case and bundle formats are versioned and may change before 1.0. It has not had an independent security audit.
supported inputsAgent endpoint records (numbat), git history, GitHub audit logs, AWS CloudTrail, and any JSON Lines, JSON or CSV export with a field mapping. OpenTelemetry, ADR Sensor and PEAC records are experimental.
verification limitsA valid signature shows that the holder of a key the recipient trusts committed to the files. It does not establish who that holder is, when the evidence was collected, whether the collection is complete, or whether the recorded events occurred. Findings are attributed judgments within a stated scope, not proof.
securityReport vulnerabilities to security@originary.xyz with the subject “Security report: originary-investigate”. Please use synthetic data only. See our security policy.

Bring the next disputed agent action to a decision.

Start with one question another team already needs answered. We will agree the scope before any evidence moves.

Investigate is open source under Apache-2.0.